cstamas commented on issue #1038:
URL: 
https://github.com/apache/maven-enforcer/issues/1038#issuecomment-5816829688

   Maven 3.6.3 is pre-COVID (2019), so for sure this cannot be considered as 
security vulnerability, since, IF this Maven version is used _today_ (FTR, it 
is 2026), we can clearly assume that given organization uses outdated tools, so 
maybe their operating systems are from 2019 as well? 😄 
   
   Jokes aside, the enforce cares about your project. It enforces they your 
project directly does not introduce this repository. Maven, by its nature (way 
of working) provides this behaviour, as it is must exactly in valid cases, like 
in your reproducer, when valid dependency must come from some other (valid) 3rd 
party repository.
   
   If you fully want to prevent this, fast forward to tools released 
post-COVID, like 2023 year is, and use Maven 3.9.7 that introduced the 
`--ignore-transitive-repositories` command line option. When you use this 
option, the **burden to collect into your POM all required repositories is on 
you (user)** with all the pros and cons, as during resolution, they are ignored 
(try it out on your reproducer). For environments you mention (ie org with some 
policies), I'd recommend this: make sure their POM (or parent POM) contains the 
"curated" remote repositories, and consistently set `-itr` for example in 
`.mvn/maven.config`. 
   
   On more serious places, there are MRMs in place, that not only cache, but 
also may enforce much more checks and policies.
   
   Again, IMHO this falls outside of enforcer (plugin), as plugin cares (and 
can care) only about your project, but this behaviour is happening at resolver 
level (much deeper), and can be triggered even by a plugin transitive 
dependency.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to